Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The Apache CXF team is proud to announce the availability of our latest patch releases!  Over 21 JIRA issues were fixed for 3.3.4, many back ported to 3.2.11.

This is mostly a patch release to fix problems and issues that users have encountered.   Downloads Downloads are available here.

Two new CVEs are fixed in these latest releases:

  • CVE-2019-12419: Apache CXF OpenId Connect token service does not properly validate the clientId
  • CVE-2019-12406: Apache CXF does not restrict the number of message attachments

August 13, 2019 - Apache CXF 3.3.3 and 3.2.10 released!

...